A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.
Reviewed by the Social Engineering Examples team.
Over the weekend of March 19-21, 2022, the LAPSUS$ extortion group (Microsoft-tracked as DEV-0537) publicly claimed to have breached Microsoft, first posting screenshots of what appeared to be internal Azure DevOps source-code repositories, then on the night of March 21 posting a torrent for a ~9GB compressed (37GB uncompressed) 7zip archive containing partial source code for over 250 internal projects, including Bing, Bing Maps, and Cortana. On the evening of March 22, 2022, Microsoft published a blog post ("DEV-0537 criminal actor targeting organizations for data exfiltration and destruction") confirming that a single employee account had been compromised, giving the group "limited access" that was used to exfiltrate portions of source code; Microsoft stated no customer code or data was involved. Microsoft's security team said it had already been investigating the compromised account based on threat intelligence before the actor's public disclosure, and that the disclosure let the team escalate its response and interrupt the actor "mid-operation." Microsoft did not disclose exactly how the specific employee account was compromised, but framed the intrusion as consistent with DEV-0537's broader documented playbook. DEV-0537 is a group that, across its 2021-2022 campaign against dozens of organizations (including Okta, Nvidia, Samsung, T-Mobile, Ubisoft, Vodafone, and Globant), relied on MFA push-bombing/fatigue, SIM swapping to hijack SMS/voice MFA, buying credentials and session tokens from criminal marketplaces, and directly paying employees, suppliers, or business partners of target organizations for network credentials and MFA approval. Two days later, on March 24, 2022, City of London Police announced the arrest of seven people aged 16-21 in connection with the LAPSUS$ investigation (one trade outlet, Computer Weekly, separately reports the arrests themselves took place March 25); researchers and the BBC identified a 16-year-old from Oxford, England (alias "White"/"Breachbase," later named as Arion Kurtaj) as an alleged ringleader who had amassed roughly $14M in Bitcoin. Two teenagers were formally charged on April 1, 2022. In August 2023, the US Cyber Safety Review Board (CISA) published a dedicated government report on LAPSUS$ documenting the group's MFA-fatigue and SIM-swap techniques in detail and citing the Microsoft compromise as an exemplar case.
Microsoft's blog did not disclose the specific initial-access technique used against its own compromised employee account, but described it as reflecting DEV-0537/LAPSUS$'s standard TTP playbook, later corroborated in detail by CISA's Cyber Safety Review Board (CSRB) report. At a general/awareness level, the group's methods were: (1) obtaining an initial foothold via purchased credentials/session tokens from criminal forums, Redline info-stealer harvests, exposed secrets in public code repos, or by directly paying an employee/contractor/supplier for login access; (2) where SMS/voice MFA protected an account, performing a SIM swap (social-engineering or bribing telecom staff/using compromised telecom employee accounts to reassign the victim's number to an attacker-controlled SIM) to intercept one-time codes; (3) where push-based MFA was in use, "MFA fatigue"/push-bombing: repeatedly triggering approval prompts (often at inconvenient hours) until the target approved one out of annoyance, or paying/soliciting an insider to simply approve the prompt themselves; (4) in some incidents, calling the target's help desk while impersonating the employee (using previously gathered personal details/profile photos and a native-English-sounding caller) to talk support staff into resetting credentials or MFA enrollment outright. Once inside, DEV-0537 used tools like AD Explorer to map privileged accounts, pivoted through Slack/Teams/Jira/Confluence to harvest further credentials, exploited known vulnerabilities in on-prem Jira/GitLab/Confluence servers, and exfiltrated data via NordVPN egress points geographically close to the victim to blend in. For Microsoft specifically, the actor reached an Azure DevOps source-code repository through the single compromised account.
There was no phishing email or deceptive message to the victim organization in the traditional sense. The "lure" operated on Microsoft's employee and/or the identity infrastructure protecting their account. Tell-tale signs the CSRB later flagged as detectable indicators across LAPSUS$ incidents generally: a sudden burst of MFA push notifications, especially clustered at odd hours (e.g., 1am) designed to wear the user down into approving one out of fatigue; help-desk contacts requesting password/MFA resets where the caller could not be verified through an out-of-band channel; and unexplained SIM/number-reassignment notifications from a carrier. LAPSUS$ itself was unusually loud afterward: it publicly announced the Microsoft compromise on its own Telegram channel and torrented a 9GB (37GB uncompressed) archive of source code before Microsoft's confirmation, which is atypical for financially motivated intrusion actors and was itself the tell that first surfaced the breach publicly.
Microsoft's security team, which was already investigating the compromised account on threat-intelligence leads before LAPSUS$'s public disclosure, used that disclosure to accelerate remediation: the account was locked down/remediated and the intrusion interrupted "mid-operation." Microsoft stated no customer code or data was affected and downplayed the severity, noting it does not rely on source-code secrecy as a security control. Separately, City of London Police announced the arrest of seven people aged 16-21 on 2022-03-24 in connection with the LAPSUS$ investigation (Computer Weekly separately reports the arrests themselves took place 2022-03-25); two teenagers (16 and 17) were charged on 2022-04-01 under the UK Computer Misuse Act and fraud statutes. The alleged ringleader, later publicly identified as Arion Kurtaj (Oxford, autistic, deemed unfit to stand trial), continued hacking while on bail (Uber, Revolut, Rockstar Games in Sept 2022); a Southwark Crown Court jury found on 2023-08-23, in a "trial of the facts" (not a conviction, given his unfitness to stand trial), that he had committed those acts, and he was sentenced 2023-12-21 to an indefinite hospital order. A 17-year-old co-defendant was convicted (an actual conviction) for related hacks of Nvidia and BT/EE. These later findings relate to Kurtaj's broader LAPSUS$-linked spree, not specifically adjudicated as the Microsoft intrusion. In August 2023, the US CISA Cyber Safety Review Board published a dedicated review of LAPSUS$ tactics (citing the Microsoft incident) with ecosystem-wide recommendations on passwordless authentication and SIM-swap controls.
This intrusion demonstrated, at a company with world-class security engineering, that identity is the new perimeter and that MFA is not a monolithic control: SMS/voice-based MFA can be defeated wholesale via SIM swapping, and even app-based push MFA can be worn down by sheer repetition (push-bombing) or simply purchased from a bribed insider. A single compromised employee account was sufficient to reach a source-code repository, illustrating how identity compromise, not sophisticated malware or zero-days, was the common thread across LAPSUS$'s breaches of Microsoft, Okta, Nvidia, Samsung, and others. It also showed that a threat actor's operational carelessness (LAPSUS$'s public bragging and poor OPSEC) can be what first surfaces and accelerates response to an otherwise-quiet intrusion, and that some of the most damaging intrusions against Fortune 500 identity/security ecosystems can be carried out by unsophisticated, teenage, loosely organized actors rather than nation-states, prompting the US government's first CSRB deep-dive into a purely criminal (non-nation-state) actor.
CISA's Cyber Safety Review Board (CSRB), in its July 24/Aug 10 2023 report on LAPSUS$, recommended: eliminating SMS- and voice-call-based MFA in favor of FIDO2-compliant phishing-resistant/passwordless authentication (number-matching push MFA is still vulnerable to fatigue attacks; hardware keys/passkeys are not); requiring explicit step-up authentication for sensitive actions rather than one-time login MFA; strict identity verification for help-desk password/MFA resets (out-of-band verification, callback to a pre-registered number, supervisor sign-off); telecom-side SIM-swap protections (account locks, strong ID verification, customer alerts) and FCC/FTC oversight of carriers; monitoring for anomalous MFA-prompt volume/timing (e.g., prompts at 1am) as a detection signal; segmenting/limiting source-code repository access and monitoring Azure DevOps/GitHub/GitLab for unusual access patterns; and organizational security-culture measures so employees report suspicious MFA prompts or bribery solicitations instead of acting on them. Microsoft's own blog echoed several of these (strong MFA, no SMS/voice MFA, employee education on social engineering, help-desk verification processes).
Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since…
Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…